Vulnerability Description
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 and the 3.x branch prior to 3.0.10 leak `Cookie` headers to cross-origin redirect targets. When following a redirect to a different origin, the `propagatedHeaders()` method in `Redirect30xInterceptor.java` strips `Authorization` and `Proxy-Authorization` headers but does not strip the `Cookie` header, causing session cookies and other sensitive cookie values to be sent to attacker-controlled servers. Versions 2.15.0 and 3.0.10 patch the issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Asynchttpclient Project | Async-Http-Client | >= 2.0.0, < 2.15.0 |
Related Weaknesses (CWE)
References
- https://github.com/AsyncHttpClient/async-http-client/commit/3b0e3e9ePatch
- https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-cliProductRelease Notes
- https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-fmExploitMitigationPatch
- https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-fmExploitMitigationPatch
FAQ
What is CVE-2026-45300?
CVE-2026-45300 is a vulnerability with a CVSS score of 7.4 (HIGH). The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 and the 3.x branch prio...
How severe is CVE-2026-45300?
CVE-2026-45300 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-45300?
Check the references section above for vendor advisories and patch information. Affected products include: Asynchttpclient Project Async-Http-Client.